Last updated: 15 August 2026
This policy explains what happens to data when you use White Noise Boat. It is short because the app does very little with data.
White Noise Boat is developed and published by 2Minds Dev, registered in Brazil under CNPJ 19.685.729/0001-77, contactable at dev@2minds.it.
We are the controller of the data described here, under Brazil's LGPD and, where it applies, the GDPR.
The app has no sign-up, no login and no ads. Sounds play from files that shipped with the app, without internet. Your choices — which sounds are on, at what volume — stay on your device.
Only two things leave your device: what a purchase needs in order to work, and usage and error measurements that carry no identifier at all — neither yours nor your device's.
We never ask for, and never receive, your name, email, phone number, contacts, precise location, photos or microphone.
The purchase is processed by the App Store or Google Play. We never see your card, your name or your email — that information stays with Apple or Google, under their own privacy policies.
To know whether your subscription is still valid we use RevenueCat, a service built for exactly that. It receives:
Legal basis (LGPD art. 7, V; GDPR art. 6(1)(b)): performance of the contract. Without this data there is no way to keep a subscription active.
This section applies from the app version in which usage measurement is included. Before that, no usage or error data leaves your device.
Two different things, which is why there are two services.
Usage, via Aptabase. When you leave the app, a single event per session is sent: which sounds you used in that session, how many, how long the app stayed open, and whether your plan is free or paid. Alongside it goes the context the service collects on its own — device model, system and app version, language and country.
That is what tells us which sounds are worth keeping. One event per session, not one per tap: we do not record the order in which you turned sounds on, nor at what time, nor how many times you tapped each one.
Errors, via Sentry. When the app crashes or fails, the technical record of the error is sent — where in the code it happened, device model and system version. Sending personal data is switched off by configuration, and there is no session replay.
Aptabase uses no identifier at all: no IDFA, no cookie, no device fingerprint, no long-term identification. It groups sessions by a cryptographic salt that is rotated every day, which makes linking you from one day to the next impossible by construction, rather than by a promise from us.
So here "anonymous" is literal, not a way of saying "pseudonymised". None of it carries your name, email or phone number — we do not have that information to send.
Legal basis (LGPD art. 7, IX; GDPR art. 6(1)(f)): legitimate interest in maintaining and improving the app. You may object — see "Your rights".
We do not collect your name, email, phone number, contacts, precise location, photos, microphone, calendar, or anything you do outside the app.
We do not track you across apps and we do not use your data for advertising. If that ever changes, the app will ask for your explicit permission first — and this policy will be updated before it does.
With no one, for any third party's own purposes.
Three suppliers act as processors: they handle the data above solely on our instructions and for the purpose described.
| Processor | What for | Policy |
|---|---|---|
| RevenueCat, Inc. | keeping your subscription valid | https://www.revenuecat.com/privacy |
| Aptabase | measuring usage, with no identifier | https://aptabase.com/legal/privacy |
| Sentry (Functional Software, Inc.) | receiving error reports | https://sentry.io/privacy/ |
This table is the complete list and is updated whenever a supplier is added or removed.
Apple and Google handle the payment itself as independent controllers, under their respective privacy policies.
We do not sell data. No data brokers and no ad networks are involved, and usage measurement is exactly what is described above — no identifier, and switchable off at any time.
The purchase record is kept while your subscription is active and for as long as tax and consumer law require the transaction to remain provable. After that it is deleted or anonymised.
Usage events and error reports are kept for up to 14 months and then deleted or turned into aggregate numbers from which no device can be recovered.
Your preferences inside the app last as long as the app is installed: uninstalling erases everything held on the device.
Under the LGPD (art. 18) and, where applicable, the GDPR, you may at any time request:
Objecting to usage measurement. Because usage measurement and error reports rest on legitimate interest, you may object to them without giving a reason. There is a switch for it in Settings → "Share anonymous usage", inside the app. It takes effect immediately — including for error reports, which stop being sent without restarting the app. Nothing in the app, paid or free, depends on accepting that measurement.
Write to dev@2minds.it. We answer within 15 days.
To request deletion, the anonymous identifier is what we need in order to locate anything; we will explain how to obtain it when you get in touch.
One honest limit: Apple and Google keep the record of your purchase independently of us, because tax law requires it. Erasing your data with us does not erase the purchase history at the store — that has to be requested from them directly.
All communication with the processors is encrypted in transit (HTTPS). Because we do not collect data that identifies you directly, the possible harm from an incident is small by construction — the best protection is the one that does without the data.
The app is not directed at children and does not knowingly collect data from them. If you believe a child in your care has provided data, write to dev@2minds.it and we will delete it.
The processors listed above keep servers outside Brazil, including in the United States. The transfer is made in order to perform the subscription contract and to keep the app working, under art. 33 of the LGPD and subject to data protection contractual clauses signed with each processor.
If anything changes materially, we will update this page and the date at the top. Changes that widen collection will be announced inside the app before they take effect.
2Minds Dev — dev@2minds.it Data Protection Officer (LGPD art. 41): dev@2minds.it